Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

FortiClient Mobile VPN not working

Hello all, We are trying to connect a HTC Diamond Windows Mobile 6.1 device to a Fortigate Firewall by VPN. Using the Windows Fortigate Client we can connect via VPN to the Fortigate without any problems. We are using routing-based VPN and manual-IP. On the Mobile Unit the FortiClient Mobile tells, that the connection is etablished but we cannot transfer data nor is the client listet in the VPN-Monitor list. I found following document: https://shop.fortinet.com/files/FortiClientMobile-ReleaseNotes.pdf Section 6.4 states, that neither DHCP nor Manual-IP is supportet. But how do I integrate the mobile device in our private network then? Perhaps someone knows a helping link or can give some hints how to configuer the VPN. Thanks a lot!
8 REPLIES 8
Not applicable

Okey, I think I have to use L2TP/IPSEC to connect the device. I wasn' t aware of this additional tunneling protocol, because I used VPN on mostly Unix devices. Refer to the FortiClient CLI handbook for further instruction about L2TP. I' ll be at the customers site in a few days again. Then I' ll tell you if it worked out.
Not applicable

MMAG Who is your mobile service provider? we use O2 and had a similar problem where the VPN comes up but no data can be transfered. speak to your mobile provider and ask them if they support VPN traffic, if they do they have to enable the service on the network. If it' s O2(UK) ask them to enable vpn.02.net (i think) and it will work, you have to do this for every number on the contract if you wish to use all devices Regards Dave
Not applicable

Thank you David for you reply. I just calles Swisscom, our provider. The gave me a new accesspoint espacially for vpn connections. I also installed the new FortiClient Mobile 4.1. But it is somehow still not working, although I have no access to the fortigate and cannot so not check the logs if something is different. I did also setup a VPN-Profile-Server. It does download the profile without any problems, but there is no indication in the log of the fortinet, that the Mobile Device even tried to connect to the fortigate. Please someone help! Thank you!
Not applicable

Jipii! It works now. Our provider had to change our mobile-accesspoint. I' ll post a documentation how to setup the whole thing in a few days. The only thing is, that DNS isn' t working jet. I still have to figure this out.
Not applicable

http://support.fortinet.com/forum/tm.asp?m=44852&p=1&tmode=1&smode=1 Check this for a quick doc.
Not applicable

If your DNS isnt working make sure you are using a virtual IP so you can set your DNS server properly.
ArcticWolf
New Contributor

I am having similar troubles, when i connect the tunnel on my touch pro it shows up in the ipsec monitor however the proxy ID destination shows as the IP from the phone provider and not the Manual Virtual IP I have programmed on the VPN client. I should mention I have upgraded to 4.1 as well but i have synced the tunnel over from my laptop. it works fine on the laptop but not on the mobile device. with testing it doesn' t appear that the IP i have indicated in the client is actually getting installed on the phone or the gateway. i downloaded a few utilities on the phone and it appears that pings and traceroutes are being routed out the IP of the phone provider and not across the tunnel. when i look the the registry on the phone i do not see the forticlient virtual adapter on the phone like I do on the laptop.
Ver 4.0 1-FG300A-hd 1-FG310B 4-FG60 6-FG60B Ver 3.0 1-FAZ800 1-FortiManager400B Ver 4.12 50-Forticlient 50-Forticlient Mobile
Ver 4.0 1-FG300A-hd 1-FG310B 4-FG60 6-FG60B Ver 3.0 1-FAZ800 1-FortiManager400B Ver 4.12 50-Forticlient 50-Forticlient Mobile
Not applicable

VirtualIP does NOT work with Windows Mobile 6.1 or lower, because virtual network adapters are not supported. You must use NAT. Check my explicit documentation here: http://support.fortinet.com/forum/tm.asp?m=44852&p=1&tmode=1&smode=1 Further (VERY IMPORTANT!): Disable reply detection in phase 2, or your Mobile device won' t be able to reconnect after it lost mobile connection for several hours. Disable auto keep alive, or your battery will only last for like 3 hours.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors